Permission usage
Why platform permissions are requested and how they are used.
Instagram permissions
instagram_business_basic identifies the Instagram professional account the user selects and reads the account identity needed to display the publishing destination.
instagram_business_content_publish creates the image, carousel, or Reel explicitly configured by the user and reads its processing status. instagram_business_manage_comments is used only when the user requests an initial Instagram comment.
TikTok permission
video.publish retrieves current Creator Info and publishes only after the user reviews the destination identity, media preview, editable caption, privacy, interactions, commercial disclosure, and the applicable TikTok declaration.
Privacy has no default, interaction controls start off, and only options returned by TikTok are shown. Selfpost does not add a watermark, logo, link, or promotional text to uploaded media.
If TikTok sign-in is enabled, user.info.basic is used only to display your name and avatar for sign-in.
YouTube permissions
youtube.upload uploads the video the user schedules to the displayed YouTube channel with the title, description, and privacy the user chooses.
youtube.force-ssl reads channel and uploaded-video details, refreshes permitted statistics, and creates an initial comment only when the user requests one. Selfpost does not subscribe, like, rate, or delete YouTube content on the user's behalf.
Google sign-in (if enabled) uses openid, email, and profile only. Revoke Google access at https://security.google.com/settings/security/permissions.
Control, storage, and revocation
Selfpost requests permissions in the account-connection flow, encrypts provider tokens at rest, and does not ask users for social-platform passwords. Disconnecting removes the local connection; disconnecting TikTok and YouTube also revokes the token at the provider immediately.
Users can revoke access at Google (https://security.google.com/settings/security/permissions), Instagram (https://www.instagram.com/accounts/manage_access/), or in TikTok's app permissions and request deletion through the published data-deletion instructions. Platform tokens are deleted immediately on disconnect; cached platform data is deleted on disconnect and otherwise refreshed or deleted within 30 days.